The 3DPrint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will create an archive of any files or directories on the target server by tricking a logged in admin into submitting a form. Furthermore the created archive has a predictable location and name, allowing the attacker to download the file if they know the time at which the form was submitted, making it possible to leak sensitive files like the WordPress configuration containing database credentials and secrets.
Conclusion & alert: CVE-2022-4023 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.08%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-09-18 | 0.25% | 0.08% | -0.17% |
| 2 | 2025-03-30 | 3.05% | 0.25% | -2.80% |
| 3 | 2025-03-29 | — | 3.05% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| 3dprint_project | 3dprint | < 3.5.6.9 | cpe:2.3:a:3dprint_project:3dprint:*:*:*:*:*:wordpress:*:* |
| URL | Tags |
|---|---|
| https://jetpack.com/blog/vulnerabilities-found-in-the-3dprint-premium-plugin/ | Exploit |
| https://wpscan.com/vulnerability/859c6e7e-2381-4d93-a526-2000b4fb8fee | Exploit Third Party Advisory |